Attackers are using fake Telegram groups and Twitter accounts to target crypto users with sophisticated scam tactics

Source Cryptopolitan

Web3 anti-scam platform Scam Sniffer has identified a new strategy by crypto scammers to target users on Telegram. In a post on X, the platform observed that these bad actors now use fake Telegram groups and the impersonation of crypto personalities.

According to Scam Sniffer, crypto bad actors rely heavily on the Telegram Safeguard Bot scam to access users’ devices and steal funds. They create fake X (formerly Twitter) accounts that impersonate crypto influencers.

They use these impersonated accounts to comment on legitimate posts, asking users to join their Telegram groups, where they share alpha and insights. However, users who join these groups are immediately prompted to verify a fake OfficialSafeguardBot.

Any user who verifies will unwittingly inject malicious PowerShell code into their clipboard. Upon executing the command, it downloads and operates malware that can compromise devices and crypto wallets. SlowMist founder Yu Xian, popularly known as Cos, noted that the malware is a Trojan horse. He said:

“When you run this Powershell command, a more complex Powershell malicious code will be downloaded covertly, and eventually the Remcos remote control Trojan will be implanted in your computer, thus compromising your computer.”

Cos further explained that there is another Telegram Safeguard scam where hackers trick users into releasing their account information. The scam tries to hack users’ Telegram accounts by asking for their mobile phone numbers or requesting that they scan a QR code and provide their login code and the two-step verification password, allowing it to control the account fully.

Fake crypto accounts are growing on X again

Meanwhile, the prevalence of the Telegram scams has also led to a rise in the number of fake crypto accounts on Twitter over the last few days. ScamSniffer reported that its monitoring systems discovered an average of 300+ fake accounts daily over the past week.

This represents a significant surge from the average of 160+ throughout November and highlights the return of the fake accounts problem to X (formerly Twitter). Although the issue appeared to have been resolved earlier this year, the resurgence in crypto prices has also led to increased crypto impersonations, suggesting a correlation between the two.

Fake Crypto Accounts
Fake crypto accounts on X rose by 87% in December (Source: Scam Sniffer)

X impersonations rose significantly between November 29 and early December, when Bitcoin rallied and broke the $100,000 mark. However, they now appear to declined, just as Bitcoin and other major caps also recorded price corrections.

These fake accounts have already made millions of unwitting victims who clicked on the malicious links. Scam Sniffer reported that two victims recently lost over $3 million to these malicious links. Several other victims also lost funds after clicking on phishing comments from fake accounts under the Pudgy Penguins tweets.

Interestingly, scammers are not just creating fake accounts; they are also compromising popular accounts to push crypto scams.

Scam Sniffer recommended several protection tips, including avoiding unknown links and software, verifying official channels, and being cautious of any time-pressured verification. As the anti-scam watchdog noted, crypto scams continue to evolve beyond simple phishing, and it is important to stay vigilant.

From Zero to Web3 Pro: Your 90-Day Career Launch Plan

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Yen Nears 160 Mark Again, Is Japan Intervention Imminent? As the US dollar continues to strengthen, the yen is once again approaching a key psychological level. During the Friday Asian trading session, USD/JPY (USDJPY) rose to near the 160 level
Author  TradingKey
Yesterday 10: 38
As the US dollar continues to strengthen, the yen is once again approaching a key psychological level. During the Friday Asian trading session, USD/JPY (USDJPY) rose to near the 160 level
placeholder
WTI climbs above $95.50 as Iran says the Strait of Hormuz must remain closed West Texas Intermediate (WTI), the US crude oil benchmark, is trading around $95.75 during the early Asian trading hours on Friday. The WTI price surges due to the effective closure of the Strait of Hormuz amid conflict involving the United States (US), Israel, and Iran.
Author  FXStreet
Yesterday 01: 19
 West Texas Intermediate (WTI), the US crude oil benchmark, is trading around $95.75 during the early Asian trading hours on Friday. The WTI price surges due to the effective closure of the Strait of Hormuz amid conflict involving the United States (US), Israel, and Iran.
placeholder
Goldman Sachs Raises Oil Price Forecasts and Warns Oil May Break All-Time Highs if Strait of Hormuz Disruption PersistsTradingKey - As tensions in the Middle East continue to escalate, concerns over supply disruptions in the energy market are heating up rapidly. Goldman Sachs' latest report raised its crude oil price
Author  TradingKey
Mar 12, Thu
TradingKey - As tensions in the Middle East continue to escalate, concerns over supply disruptions in the energy market are heating up rapidly. Goldman Sachs' latest report raised its crude oil price
placeholder
SEC, CFTC move past turf battle as Bitcoin approaches $70KThe SEC and the CFTC entered into a memorandum of understanding to work together on a regulatory framework.
Author  Cryptopolitan
Mar 12, Thu
The SEC and the CFTC entered into a memorandum of understanding to work together on a regulatory framework.
placeholder
Gold weakens as inflation concerns lift US bond yields and USD; downside remains cushionedGold (XAU/USD) trades with a negative bias for the second consecutive day on Thursday, though it lacks follow-through selling and stalls the intraday slide near the $5,125 area.
Author  FXStreet
Mar 12, Thu
Gold (XAU/USD) trades with a negative bias for the second consecutive day on Thursday, though it lacks follow-through selling and stalls the intraday slide near the $5,125 area.
goTop
quote